Toward trusted container networking: hardware enforced secure network isolation하드웨어 기반 네트워크 격리를 통한 신뢰할수 있는 컨테이너 네트워킹

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 120
  • Download : 0
As containerization emerges as a lightweight virtualization technology for cloud services, the security of containers has become an important subject especially in inter-container networking, which is the basis of the modern microservice architecture. On the one side, inter-container networking enables large-scale microservice deployment, on the other side, it opens a new window for adversaries who own a compromised container to paralyze neighboring containers through network-level attacks. In spite of such threats, today’s security solutions for containers not only degrade network performance but also have severe security holes in protecting containers from such network-level attacks. To address such problems, we present Hyperion, a novel hardware-assisted network isolation and security enforcement system for inter-container communications. This system effectively protects containers from a wide range of network attacks by complementing the security holes in today's solutions while ensuring network performance. Hyperion provides agile-yet-secure inter-container networking through (i) physically isolated communication channels for containers using its secure networking bridge on a physical NIC and (ii) three security features (i.e., source signing, hardware-offloaded policy enforcement and payload inspection). Our evaluation shows that Hyperion prevents a variety of network attacks initiated from both container- and host-side, and it performs six times faster than the state-of-the-art security solutions.
Advisors
Shin, Seungwonresearcher신승원researcher
Description
한국과학기술원 :정보보호대학원,
Publisher
한국과학기술원
Issue Date
2022
Identifier
325007
Language
eng
Description

학위논문(석사) - 한국과학기술원 : 정보보호대학원, 2022.2,[v, 33 p. :]

URI
http://hdl.handle.net/10203/309620
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=997747&flag=dissertation
Appears in Collection
IS-Theses_Master(석사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0